Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
ryan-c
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
31 ms
·
241.
▲
by
ryan-c
5y ago
I remember attending Dan Kaminsky’s talk at DEFCON 12 and being blown away by it. Three years later, I went on the original “Hackers on a Plane” trip and ended up seated next to Dan on one of the flights. We quickly became friends. His ment
242.
▲
by
ryan-c
6y ago
...interesting
243.
▲
by
ryan-c
6y ago
...and for this "display some art" hack specifically, it looked like it can be made to work with plain git log by using `\r` characters as newlines in addition to the escape sequences, but I haven't tested that much.
244.
▲
by
ryan-c
6y ago
I was honestly more surprised at how much data I could fit in that field. Git itself doesn't appear to have any limit at all, though GitHub doesn't allow more than a few dozen megabytes.
245.
▲
by
ryan-c
6y ago
Oh, wow, I'd heard of the unix haters handbook, but I never realized it was an actual published book.
246.
▲
by
ryan-c
6y ago
I found Brian when someone I follow retweeted (or perhaps liked?) this post: https://twitter.com/cmmrc2/status/1329991505524690944 I'd been looking for an artist for months at that point, and looked through h
247.
▲
by
ryan-c
6y ago
Yes, but there's a 32 byte limit which is a bit of a buzzkill.
248.
▲
by
ryan-c
6y ago
For animation, the real issue is frame timing. It looks like there's an animation API in kitty that allows this sort of control, so it'd work there, and iTerm2 supports inline animated gifs which I've already demo'd.
249.
▲
by
ryan-c
6y ago
It was still stuffed in the author email field.
250.
▲
by
ryan-c
6y ago
It's a bit more complicated than that. For example, if you do git log --format=%ae | sort -u the cursor movement sequences will be preserved. I haven't delved too deeply into what git actually does here in terms of processing for
251.
▲
by
ryan-c
6y ago
Yeah, it's kind of my thing :-) One of the previous times I hit the front page of HN it was for inserting snark into an X509 certificate and then using it on my site. https://rya.nc/cert-tricks.html
252.
▲
I encoded my avatar in a Git commit email field
(twitter.com)
3 points
by
ryan-c
6y ago
|
0 comments
253.
▲
by
ryan-c
6y ago
If you're a low volume email sender, anything attributed to your domain getting marked as spam can cause serious pain. It's an interesting idea, but not an experiment I care to run.
254.
▲
by
ryan-c
6y ago
My reply was more to what tptacek said - observing that for at least some configurations a stolen mail spool from a laptop won't have signatures on sent emails.
255.
▲
by
ryan-c
6y ago
I was not, thank you for the link. I've been running my key disclosures for over three years, Matthew Green's Tweet about it motivated me to write it up.
256.
▲
by
ryan-c
6y ago
Attack: Sign up for email accounts at major providers, use the signing oracle to sign spam emails, submit to provider, domain's reputation becomes spammy. The handling rules standardized by DMARC are to ignore failing SPF when there is
257.
▲
by
ryan-c
6y ago
Just to be clear, the post is about minimizing the limited non-repudiation properties that DKIM is currently giving email as a side effect. > I would consider it a very poor idea to have a set of automatic scripts messing around with the
258.
▲
by
ryan-c
6y ago
I'm not a he, but you're correct that a counterparty can easily break delayed key disclosure as a way to have plausible deniability. This was brought up in the Twitter thread (though reading a conversation on Twitter that has any
259.
▲
by
ryan-c
6y ago
I'm not sure how common it is, but my mail server in particular doesn't store the signed emails, and I went to no special effort to set things up that way. Of course, if someone replies to me and quotes my email to them, that will
260.
▲
by
ryan-c
6y ago
Automatic DKIM key rotation is common, I'm talking about publishing private keys.
261.
▲
DKIM: Show Your Privates
(rya.nc)
132 points
by
ryan-c
6y ago
|
72 comments
262.
▲
by
ryan-c
6y ago
Oddly, I have actually been told in the past by PayPal to file a $1500 dispute with my credit card company (AmEx in my case) because for whatever reason they couldn't handle it internally. Didn't get banned.
263.
▲
by
ryan-c
6y ago
I think this might be a good use case for history.replaceState - it'll change the URL in the address bar without actually redirecting.
264.
▲
by
ryan-c
6y ago
100% certain, but it's self signed, so no mainstream browser will honor it.
265.
▲
by
ryan-c
6y ago
I think you may have missed that my comment was primarilly a terrible pun.
266.
▲
by
ryan-c
6y ago
Nor are they permitted anywhere other than in the leftmost part of the name. *.*.example.com and foo.*.example.com aren't allowed. Not sure what the current state of software accepting these things is, but minimally, CAs
267.
▲
by
ryan-c
6y ago
> they could remove my hard drive and insert it into an identical laptop Does that make having a layer of stickers on one's laptop also a layer of defense?
268.
▲
by
ryan-c
6y ago
Are there protected classes based on political views? If someone is expressing political or even religious views that are so extreme that they create a hostile work environment, I don't see an issue with firing them over it. (I am not
269.
▲
by
ryan-c
7y ago
They commingle reviews for multiple "related" products too.
270.
▲
by
ryan-c
7y ago
This is a bad idea because if you can generate your key from a passphrase, everyone else in the world can do so also. This tool "helpfully" tags all keys it generates (via timestamp = 0) to announce the potential vulnerability. Ye
More ›